FROM ghcr.io/berriai/litellm:main-v1.74.0-stable

# LiteLLM's official image runs as root. Cloudron's sandboxing (read-only
# rootfs, AppArmor, dropped capabilities) still applies to root inside the
# container, so we keep root to match the base image and avoid /app/data
# volume-ownership issues.

# Create the data directory (Cloudron mounts the localstorage volume here)
RUN mkdir -p /app/data /app/code

# Create a startup script that configures LiteLLM with Cloudron addons
COPY start.sh /app/code/start.sh
RUN chmod +x /app/code/start.sh

# Default config — will be overridden by Cloudron env vars at runtime
COPY config.yaml /app/data/config.yaml

# Override the base image's ENTRYPOINT (which is `litellm`) so our
# startup script runs instead of being passed as an argument to litellm.
ENTRYPOINT ["/app/code/start.sh"]

# LiteLLM v1.74.0 hardcodes `origins = ["*"]` (with allow_credentials=True) in
# proxy_server.py and ignores LITELLM_CORS_ALLOWED_ORIGINS entirely. Rewrite it
# to honour the env var so we can lock CORS to the chat origin. Patch every copy
# (site-packages is what the running CLI imports; /app/litellm is a dev copy).
RUN sed -i 's/^origins = \["\*"\]$/import os; origins = os.getenv("LITELLM_CORS_ALLOWED_ORIGINS", "*").split(",")/' \
      /usr/lib/python3.13/site-packages/litellm/proxy/proxy_server.py \
      /app/litellm/proxy/proxy_server.py
